Description
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html

* https://w4ke.info/2025/10/29/funky-chunks-2.html


Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error.




POST / HTTP/1.1
Host: localhost
Transfer-Encoding: chunked

1;ext="val
X
0

GET /smuggled HTTP/1.1
...





Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
Published: 2026-04-14
Score: 7.4 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from the Eclipse Jetty HTTP/1.1 parser failing to correctly terminate chunk extensions that contain unclosed quoted strings; the parser treats a CRLF within a quoted string as the end of the extension instead of raising an error, enabling an attacker to craft a chunked request that embeds a second, separate HTTP request. The flaw is classified as CWE-444 and allows remote HTTP request smuggling, potentially bypassing authentication or routing controls in downstream services.

Affected Systems

All installations of Eclipse Jetty that lack the published fix are vulnerable; this includes the open‑source Jetty server as used by organizations such as Red Hat and other systems that embed Jetty. No particular version range was specified in the advisory, so any Jetty release prior to the patched version should be considered at risk until the update is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.4, indicating high severity, while the EPSS score of 1% reflects a low but non‑zero likelihood of exploitation. It is not listed in CISA KEV. An attacker can exploit the flaw remotely over the network by sending a crafted chunked request with an improperly closed quoted string; no authentication or local privileges are required. Successful exploitation could allow the injected request to reach downstream services undetected, potentially granting unauthorized access or causing service disruption.

Generated by OpenCVE AI on August 17, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Eclipse Jetty to the latest release that includes the CVE‑2026‑2332 fix.
  • If a patch is not yet available, configure front‑end proxies or firewalls to reject or strictly validate Transfer‑Encoding: chunked requests that contain malformed chunk extensions or unclosed quoted strings.
  • Continuously monitor Jetty security advisories and deploy subsequent patches as they are released.

Generated by OpenCVE AI on August 17, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-355h-qmc2-wpwf Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
History

Wed, 26 Aug 2026 15:45:00 +0000


Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request. In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.

Fri, 01 May 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

Thu, 16 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse jetty
Vendors & Products Eclipse
Eclipse jetty

Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 11:30:00 +0000

Type Values Removed Values Added
Description In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
Title HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-08-26T12:04:56.948Z

Reserved: 2026-02-11T09:56:25.879Z

Link: CVE-2026-2332

cve-icon Vulnrichment

Updated: 2026-08-26T12:04:56.948Z

cve-icon NVD

Status : Modified

Published: 2026-04-14T12:16:21.333

Modified: 2026-08-26T13:18:09.467

Link: CVE-2026-2332

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-14T10:59:10Z

Links: CVE-2026-2332 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T21:45:03Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')